# Groupby servers by custom field in infrastructure Dashboard

**URL:** <https://discuss.elastic.co/t/groupby-servers-by-custom-field-in-infrastructure-dashboard/174663>\
**Category:** Metrics\
**Created:** [March 31, 2019, 8:01am UTC](https://discuss.elastic.co/t/groupby-servers-by-custom-field-in-infrastructure-dashboard/174663 "2019-03-31T08:01:39Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![syedsfayaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syedsfayaz/32/46657_2.png) [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Post date:** [March 31, 2019, 8:01am UTC](https://discuss.elastic.co/t/groupby-servers-by-custom-field-in-infrastructure-dashboard/174663/1 "2019-03-31T08:01:39Z")

</div>

I am able to see servers in Infrastructure dashboard. But I want to categorize(group by) them by a custom field like env name. Is there any configuration in Kibana or Metricbeats configuration where I can configure this.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [April 1, 2019, 8:54am UTC](https://discuss.elastic.co/t/groupby-servers-by-custom-field-in-infrastructure-dashboard/174663/2 "2019-04-01T08:54:54Z")

</div>

Hi @syedsfayaz,

controls for custom grouping in the Infrastructure UI will be part of the upcoming 6.7 release of the Elastic Stack: [https://github.com/elastic/kibana/pull/28949](https://github.com/elastic/kibana/pull/28949)

![grafik](https://us1.discourse-cdn.com/elastic/original/3X/2/7/2746e6e515f25ca620e550e194b2e158f96d1047.png)

As long as the field is of type `keyword` it will be available for grouping.

---

<div class="post-metadata">

**Author:** ![syedsfayaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syedsfayaz/32/46657_2.png) [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Post date:** [April 1, 2019, 9:17pm UTC](https://discuss.elastic.co/t/groupby-servers-by-custom-field-in-infrastructure-dashboard/174663/3 "2019-04-01T21:17:39Z")

</div>

@weltenwort Any idea when will this feature be realising or is it available in alpha or beta version now?

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [April 1, 2019, 9:30pm UTC](https://discuss.elastic.co/t/groupby-servers-by-custom-field-in-infrastructure-dashboard/174663/4 "2019-04-01T21:30:10Z")

</div>

6.7 release is available in general availability, as of last week.

---

<div class="post-metadata">

**Author:** ![syedsfayaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syedsfayaz/32/46657_2.png) [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Post date:** [April 1, 2019, 9:32pm UTC](https://discuss.elastic.co/t/groupby-servers-by-custom-field-in-infrastructure-dashboard/174663/5 "2019-04-01T21:32:21Z")

</div>

Thank you.

---

<div class="post-metadata">

**Author:** ![syedsfayaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syedsfayaz/32/46657_2.png) [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Post date:** [April 8, 2019, 6:35pm UTC](https://discuss.elastic.co/t/groupby-servers-by-custom-field-in-infrastructure-dashboard/174663/6 "2019-04-08T18:35:56Z")

</div>

@tbragin @weltenwort

I have upgraded my Kibana and Elastic search to 6.7.1 but I am unable to use this feature.

I have a field which I set in Metricbeats.

Fields.env = "xyz" I can see this field in discover but when I go to infrastructure dashboard I am unable to group by this field.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/f/ef8d8da2ec1e7b75853bae5153ab2983af56f73e.png)

Infrastructure Dashboard.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/3/c3dc0a7090fb6d17cc34982e872a79c87b14e121.png)

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [April 8, 2019, 6:40pm UTC](https://discuss.elastic.co/t/groupby-servers-by-custom-field-in-infrastructure-dashboard/174663/7 "2019-04-08T18:40:46Z")

</div>

The field icon in your screenshot suggest that this is a numeric field. This is probably due to the lack of static mapping for that custom field, which causes Elasticsearch to dynamically (and potentially incorrectly) choose one.

![grafik](https://us1.discourse-cdn.com/elastic/original/3X/d/d/dd8419917297346ce530d9fd7c5423b6a70e5e34.png)

In order to group by a field it must be of the `keyword` type. I would recommend to add the custom fields to the index template to ensure that.

---

<div class="post-metadata">

**Author:** ![syedsfayaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syedsfayaz/32/46657_2.png) [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Post date:** [April 8, 2019, 6:51pm UTC](https://discuss.elastic.co/t/groupby-servers-by-custom-field-in-infrastructure-dashboard/174663/8 "2019-04-08T18:51:38Z")

</div>

@weltenwort Thanks for your reply. I am able to fix this by adding a new field.

field.version = "10.6" which it considers as a string.

Now, as I have already installed beats on different servers. Can I just fix the existing mapping

fileds.env = "10.6". I know elastic search might have already stored this value as a float.

But Is there a way to fix it?

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [April 8, 2019, 10:26pm UTC](https://discuss.elastic.co/t/groupby-servers-by-custom-field-in-infrastructure-dashboard/174663/9 "2019-04-08T22:26:35Z")

</div>

Changing the type of a field mapping in an index after it has been set is indeed not possible. The recommended way to effectively achieve this is to use the [reindex api](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html) to copy the documents into a new index while adjusting the field with a painless script. That could roughly look like this:

```json
POST _reindex
{
  "source": {
    "index": "filebeat-6.7.0-2019-04-08",
  },
  "dest": {
    "index": "filebeat-6.7.0-2019-04-08-2"
  },
  "script": {
    "source": "ctx._source.fields.env = ctx._source.fields.env.toString()",
    "lang": "painless"
  }
}

```

A few points of note:

- The new index name should match the metricbeat index pattern so the correct mapping gets applied.
- This assumes that every doc has a `fields.env` field. You might have to guard against it with something like `if(ctx._source.fields?.env != null) { ... }`.
- It might be a good idea to make sure the resulting index contains the desired documents before deleting the source and to back up the source beforehand.

---

<div class="post-metadata">

**Author:** ![syedsfayaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syedsfayaz/32/46657_2.png) [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Post date:** [April 8, 2019, 11:16pm UTC](https://discuss.elastic.co/t/groupby-servers-by-custom-field-in-infrastructure-dashboard/174663/10 "2019-04-08T23:16:37Z")

</div>

@weltenwort Thanks for your reply.

I also noticed that the different colors which I was seeing in old kibana dashboard is not available.  
I can just see plain blue colour.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/d/cdad72ec8fd2397df2170482f8962c681c95d74d.png)

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [April 9, 2019, 9:28am UTC](https://discuss.elastic.co/t/groupby-servers-by-custom-field-in-infrastructure-dashboard/174663/11 "2019-04-09T09:28:33Z")

</div>

The colors were changed to a blue/gray palette in [PR #28206](https://github.com/elastic/kibana/pull/28206) due to user feedback.

For some the red/green color incorrectly suggested a judgement of the metric, which is not generally correct. A near 100% CPU utilization while meeting all the SLAs might indicate that your host is appropriately sized and doesn't waste any resources.

More importantly, the red/green scheme was not accessible for people with common color vision impairments. Ideally we would offer a choice of the color palette to you. Any feature requests on Github would be very welcome.

---

<div class="post-metadata">

**Author:** ![syedsfayaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syedsfayaz/32/46657_2.png) [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Post date:** [April 9, 2019, 4:39pm UTC](https://discuss.elastic.co/t/groupby-servers-by-custom-field-in-infrastructure-dashboard/174663/12 "2019-04-09T16:39:04Z")

</div>

@weltenwort I am fine with what we have now. I was just curious coz the colors looked good in 6.6 and was not seeing them in the upgraded version.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2019, 4:39pm UTC](https://discuss.elastic.co/t/groupby-servers-by-custom-field-in-infrastructure-dashboard/174663/13 "2019-05-07T16:39:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
